AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T17:18:18.450Z and has not been modified since then. The rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php [truncated]
CVE-2026-77914 is a path traversal vulnerability in rConfig Core versions before 8.2.13. Authenticated users can exploit this vulnerability to read arbitrary files by manipulating the filename parameter in the export download endpoint with directory traversal sequences. This vulnerability allows attackers to access sensitive files, potentially leading to data exposure and unauthorized file access. Defende [truncated]
CVE-2026-64826 is a path traversal vulnerability in rConfig before 8.2.13 that allows authenticated attackers to read arbitrary files. The vulnerability exists in the download_export() method and can be exploited by supplying unsanitized directory traversal sequences in the filename GET parameter. This could lead to unauthorized access to sensitive configurations and credentials, potentially exposing encr [truncated]
CVE-2026-63102 is a medium-severity privilege escalation vulnerability in rConfig Core before 8.2.8. The vulnerability allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest [truncated]
CVE-2020-10221 is an OS command injection vulnerability in rConfig. CISA lists it in the Known Exploited Vulnerabilities (KEV) catalog, which means there is evidence of active exploitation and the issue should be treated as a defensive priority. The supplied corpus does not include affected version details or a vendor advisory, so remediation should follow vendor update guidance and be paired with exposur [truncated]